Honeypots mailing list archives

Postfix as honeypot and other anti-spam related Qs


From: Stef <stefmit () comcast net>
Date: Sun, 8 Feb 2004 15:50:12 -0600

I have been trying to design an anti-spam honeypot, utilizing (because this is what I have at my disposal) a postfix server. I have gone through the following material:

http://www.trackinghackers.com/solutions/sendmail.html
http://www.securityfocus.com/infocus/1747
http://www.securityfocus.com/infocus/1748

and I liked the first one. Here are the issues I am dealing with, right now: - cannot find the equivalent of some the options mentioned in the sendmail-based article, related to postfix; - wondering if there could be more about such a setup, as far as logging/processing of logs/reporting (perhaps automatic - I am thinking here of some automatic way of informing the spamcop.net of the world?!?)

Any ideas/suggestions/links to help me understanding what more could I get out of the above, and postfix capabilities, would be highly appreciated.

One more note/question: the plan is to take a static public IP of a system I have available, and use it as MX record for a new domain I will be registering, via dyndns (so that my honeypot could be found as such by MX record scanning of domains, not only by TCP 25 scanning). I wonder what would be the chance that spammers would have tools to reverse lookup the IP address, and find out that the IP belongs in fact to another domain (i.e. I cannot - obviously - change the PTR record for an IP address!). And if found as such - what would be the chance to stop pursuing the "sweets"? Any ideas?!?

TIA,
Stef


Current thread: